CWE-400
High likelihoodUncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
3,367 vulnerabilities with CWE-400
CVE-2026-55497
MEDIUM
Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)
CVSS 6.5
CVE-2026-10695
MEDIUM
IBM® Db2® is vulnerable to a denial of service when running non fenced federated queries
CVSS 6.2
CVE-2026-9322
HIGH
IBM WebSphere Application Server and Liberty - Denial of Service
CVSS 7.5
CVE-2026-67437
HIGH
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
CVSS 7.5
CVE-2026-63119
MEDIUM
MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)
CVSS 6.2
CVE-2026-16543
HIGH
Kong Operator cluster-wide ingress configuration DoS via embedded KIC CA-certificate ID collision
CVE-2026-15228
HIGH
Kong Kubernetes Ingress Controller cluster-wide ingress configuration DoS via CA-certificate ID collision
CVE-2026-58182
HIGH
Apache Traffic Server: ts_lua plugin has initialization and resource-handling errors
CVSS 8.6
CVE-2026-65324
HIGH
Apache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion
CVSS 7.5
CVE-2026-58151
HIGH
Apache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash the server
CVSS 7.5
CVE-2026-59942
MEDIUM
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps
CVE-2026-59941
MEDIUM
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions
CVE-2026-14981
HIGH
IBM WebSphere Application Server and Liberty - HTTP Channel Denial of Service
CVSS 7.5
CVE-2026-59932
HIGH
PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
CVSS 7.5
CVE-2026-59933
HIGH
PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
CVSS 7.5
CVE-2026-54609
HIGH
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
CVSS 8.6
CVE-2026-66299
HIGH
Apache Tomcat: DoS via WebSocket chat example
CVSS 7.5
CVE-2026-66920
HIGH
Pivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph Data
CVE-2026-66913
MEDIUM
Zip Bomb in Lookyloo Capture Upload Allows Denial of Service
CVE-2026-42493
HIGH
x86 shadow paging is deprecated
CVSS 7.5
CVE-2026-55685
HIGH
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
CVE-2026-64724
MEDIUM
Apple Ios And iPadOS - Denial of Service
CVSS 5.5
CVE-2026-43806
MEDIUM
Apple macOS < 26.6 - Denial of Service
CVSS 5.5
CVE-2026-43804
MEDIUM
Apple Safari - Denial of Service
CVSS 6.5
CVE-2026-43768
MEDIUM
macOS < 14.8.8, < 15.7.8, < 26.6 - Denial of Service via Memory Handling Issue
CVSS 5.5
Details
Vulnerabilities
3,367
Exploit Likelihood
High